Luke Dashjr Identifies Bitcoin Vulnerability
Luke Dashjr, a Bitcoin developer and CTO of Mummalin, has discovered a vulnerability in the Bitcoin blockchain that allows Ordinal inscriptions to embed data directly onto the chain. The vulnerability, known as CVE-2023-50428, explains how the Ordinals protocol can obfuscate and incorporate data into the blockchain.
Description of the Vulnerability
The vulnerability description states that datacarrier size limits can be bypassed by disguising data as code, as demonstrated by Inscriptions in 2022 and 2023. This exploit has received a medium threat level of 5.3 in the National Vulnerability Database (NVD) maintained by the National Institute of Standards and Technology (NIST).
Controversy and Criticism
Luke Dashjr intends to address this bug and fix it in the next release of the Bitcoin Core full node software. However, his proposed solution has received significant backlash from the Bitcoin community. Other developers have rejected the fix, arguing that it may lead to the development of private mempools and make fee estimation less reliable. Dashjr’s approach has also been criticized for not incentivizing the use of less harmful methods to prevent spam on the blockchain.
Impact on Ocean Mining Pool
Ocean, a Bitcoin mining pool operated by Mummalin, utilizes a version of Bitcoin Core called Knots developed by Dashjr. This fork has faced criticism for censoring private transactions from Samourai Wallet after implementing the fix for Ordinal inscriptions.
Hot Take: Bitcoin Developer Identifies Vulnerability in Blockchain
A vulnerability discovered by Luke Dashjr, a Bitcoin developer, has highlighted the potential for Ordinal inscriptions to embed data on the Bitcoin blockchain. This vulnerability, known as CVE-2023-50428, bypasses datacarrier limits by obfuscating data as code, posing a medium threat according to the NIST’s NVD. Dashjr’s proposed fix has sparked controversy within the Bitcoin community, with concerns about revenue loss for miners and the effectiveness of the solution. The impact on Mummalin’s Ocean mining pool, which utilizes Dashjr’s version of Bitcoin Core, has further intensified the debate. The community seeks innovative alternatives to address the vulnerability without negative repercussions.